Log file from rsyslog

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
floki
Posts: 65
Joined: Tue Dec 18, 2018 5:23 am

Log file from rsyslog

Post by floki »

Good Day,

After I restart rsyslog in a monitored server by nagios log server. It generated a file named: nls-state-opt_snort-alerts_major.log

Code: Select all

<Obj:1:strm:1:
+iCurrFNum:2:1:1:
+pszFName:1:27:/opt/snort-alerts/major.log:
+iMaxFiles:2:1:0:
+bDeleteOnClose:2:1:0:
+sType:2:1:2:
+tOperationsMode:2:1:1:
+tOpenMode:2:3:384:
+iCurrOffs:2:1:0:
+inode:2:1:0:
+bPrevWasNL:2:1:0:
>End
How do you interpret the files generate from /var/lib/rsyslog?
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Log file from rsyslog

Post by scottwilkerson »

This file is used to keep track of the offset in the file so rsyslog knows where it left off the last time it looked in the file for new lines to send to Log Server.

This file is created as a function of rsyslog.
Former Nagios employee
Creator:
ahumandesign.com
enneagrams.com
floki
Posts: 65
Joined: Tue Dec 18, 2018 5:23 am

Re: Log file from rsyslog

Post by floki »

Alright, understood. Thanks a lot!
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Log file from rsyslog

Post by scottwilkerson »

floki wrote:Alright, understood. Thanks a lot!
Glad to help.

Locking thread
Former Nagios employee
Creator:
ahumandesign.com
enneagrams.com
Locked